Microsoft Purview Data Protection – Configure the Restricted App Groups

A common method for data to exit an organization’s control is through third-party applications.  These applications can be cloud storage like Dropbox or Google Drive.  They can also be applications such as Grammarly with access to a cloud infrastructure.  To support the control of this, it is possible to create Data Loss Prevention (DLP) policies that monitor when data is accessed by these applications.  The DLP policies can even block the content from being accessed by the applications should the organization determine this is necessary to protect their environment.  In this post, we’ll cover the steps to configure Purview’s DLP settings that assist administrators in monitoring and blocking content being accessed by third-party applications by demonstrating how to configure the Restricted App Groups section of DLP.

As always, please be aware of my blog disclaimer

Configure the Restricted App Groups

The configuration to be made is to be done within the settings section of the Purview Data Loss Prevention solution.  Fair warning if you haven’t been in the settings before; there are a lot of settings to choose from.  Specifically, the category we are looking for is “Restricted Apps and app groups“.  You will also need one of the following roles:

  • Global Adminstrator
  • Compliance administrator
  • Compliance data administrator
  • Information Protection
  • Information Protection Admin
  • Security administrator
  1. Login to Microsoft Purview (https://purview.microsoft.com).
  2. Click on the settings cog (top right-hand corner) and select Data Loss Prevention.

Configure the Sensitive Service Domain Groups - DLP Settings in Purview

  1. Next, scroll down and click on Restricted apps and app groups.
  2. You can add apps individually, but it makes more sense to group them together, so click on the + Add app group

Configure the Restricted App Groups - Restricted apps and app groups

  1. Provide a meaningful name to the group, add the app name, and executable the policy will need to watch for.

Configure the Restricted App Groups - Add Restricted App Group

  1. Once all apps are added., click Save.

Once the restricted app group is prepared, you can use DLP policies to target the sharing of sensitive information via installed apps in your environment.

 

Thanks for reading!


I’d love to share regularly with you!

Subscribe to get the latest posts sent to your email.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *